Phishing tries to trick you into typing your credentials or 2FA codes into a fake copy of a legitimate site. It is the most common attack against crypto users — and entirely avoidable with a few habits.
The red flags
- Urgency: “your account will be suspended in 24 hours” — pressure is the attacker's main tool.
- Look-alike domains: palzea-support.com, palzea.help, pa1zea.com. Always check the address bar character by character.
- Unsolicited attachments or links in emails, Telegram or Discord messages.
- Anyone asking for your password, 2FA code or seed phrase. Staff never need them — anyone who asks is an attacker, full stop.
Habits that keep you safe
- Bookmark the real site and always enter through the bookmark.
- Enable 2FA with an authenticator app (see the dedicated article).
- Use a unique password for Palzea, stored in a password manager.
- Treat every “support agent” who contacts you first as hostile — real support only replies when you open a request.
If you typed your credentials into a suspicious page, change your password immediately and contact support to freeze withdrawals.


